Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:9242db751ec30e0553f6c316b260c2d8a409bc8d1c7282213b7bad7fc690b85b

Manifest digest:

sha256:9dc8960c7d812513412240dffe6ef8efd9c9f7b4871dd6702935b5873f4505d9

Size

19.67 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7c6e52aef699dc365005186d57f6a2935affb311be7b348e3f9e098840a36b6d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:057eb0e0da3201dcc65d380614994bdafc11010e2061a2521ee95098f7a8de88
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ea3d299203e57b60cc72c41942170101ea729a870a9fcb6d2e745993de27e184
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2ef38259eaa3fc016114c401fce12f2e3bb7f63256446160239ee26ccc9f348a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:905527b1215bac9eb0dc84b467db92ca1ceb58c763bbc76a06ca2372c9536f52
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:90cccb6224b7f9efe15876622c0cc2e8f7be6b1f50ba6d2886ccf27d8010935b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:b935f7c8e230b2f1db5bc55503c2e527481a37c350656c25bf9033dc56e94525
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:b8080d30467c6ac70dc8eb825dbebf9fb9f9934855383195c0948ef6b28193a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:16b769fd5f5f306b77c344ec09ffcbbf98b452dec40cb0040e3f25a3cdb166d5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:56537b979332da017d54b27b991782b6e452425c3fa826cbdda8e69cf0b47260
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:09b835daad1d15a76b586398b9be5edfaa9afcf0c7af143536dd03a75bb92dec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:cc7170eee8994264a28244d6a79147492422f0a72f3ed16acda25e57ecea87cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ccdf94436ce432671a68829be3d921d383df5e0fcedd8ea92c6b72eaaa47b2f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:72a8b23c89679ed470970af4da1653cc7008afcc3cd21b67b7cff2610ce7218c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3a18e3cddba0f97eaf5231c617381169ca641ada630a2629d9a4b58663b31820
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:7197d73ce85bc65d4abc9642a189a79121fa58a8dda766cfe7d908813d88fd2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:904764fdaba30fc340da63e45dc8ac69f71f49bb18f9c698a4baea6a8e02e37c